CWE-88
430 CVEs • Abstraction: Base
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CVEs (430)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectFirejail Project+1 more4Debian Linux FedoraFirejail+1 moreJun 17, 2026 Aug 11, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection. |
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attac...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jul 16, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system. The vul...Show more |
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument deli...Show more |
Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either rela...Show more |
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen. |
1Se 1Ecostruxure Operator Terminal Expert Jun 17, 2026 Jun 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening...Show more |
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it. |
1Redhat 4Ansible Ansible TowerCloudforms Management Engine+1 moreJun 17, 2026 Mar 16, 2020 N/A· v4 3.9 LOW· v3 2.6 LOW· v2 A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacke...Show more |
1Mitsubishielectric 1Iu1 1m20 D Firmware Jun 17, 2026 Mar 16, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and ear...Show more |
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation sho...Show more |
An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the start/stopLaunchDProcess command. The command takes a user-supplied string argument and execute...Show more |
An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the startProcess command. The command takes a user-supplied script argument and executes it under r...Show more |
1Sangoma 1Session Border Controller Firmware Jun 17, 2026 Oct 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successfu...Show more |
1Sangoma 1Session Border Controller Firmware Jun 17, 2026 Oct 22, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can cr...Show more |
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to...Show more |
rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of service (loop of conn_event and ready) by arranging for a client to never be writable. |
3Fedoraproject Mixin Deep ProjectOracle3Communications Cloud Native Core Network Function Cloud Native Environment FedoraMixin DeepJun 17, 2026 Aug 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. |
cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh. |